📰 DAILY THREAT BRIEFING
Saturday, May 23, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of May 23, 2026.

  1. First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
    — The Hacker News

    Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal …
  2. Netherlands seizes 800 servers of hosting firm enabling cyberattacks
    — Bleeping Computer

    Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled…
  3. Lawmakers Demand Answers as CISA Tries to Contain Data Leak
    — Krebs on Security

    Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOn…
  4. Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
    — The Hacker News

    The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been obs…
  5. Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers
    — Dark Reading

    When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their produc…
  6. Former US execs plead guilty to aiding tech support scammers
    — Bleeping Computer

    Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that vict…
  7. Trend Micro warns of Apex One zero-day exploited in the wild
    — Bleeping Computer

    Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows …
  8. Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks
    — Dark Reading

    Ransomware and vendor breaches persist. The "2026 Data Breach Investigations Report" (DBIR) highlights how evolving social engineering tacti…
  9. Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
    — Unit 42

    Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campa…
  10. Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
    — The Hacker News

    Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,5…
  11. Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
    — Unit 42

    Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Pa…
  12. China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments
    — Dark Reading

    The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim…

Generated by CryptXNet.ai Threat Intelligence Platform · May 23, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com